Dynamic Group Key Management in Outsourced Databases
Alla Lanovenko, Huiping Guo · 2007
Abstract—Database outsourcing is becoming increasingly popular, which leads to a new scenario, called database-as-a-service where an organization’s database is stored at an external service provider[14]. In such a scenario, it’s very important to control the access to the database if the data owner wishes to publish his or her data for external use. Previous researchers had made many efforts in designing and querying encrypted outsourced databases aiming at protecting data on the server side. However, protecting outsourced database from the unauthorized access on the client side is still an open issue. Since, knowledge of the decryption key allows clients to not only access authorized data, but also the entire outsourced database, which violates data confidentiality and owners privacy. This paper addresses one of the major deficiencies of the outsourced database model: confidentiality. We propose a key management schema which is suitable for the dynamic environment. This schema can be efficiently applied to the outsourced databases and is based on the widely used Rivest-Shamir-Adelman (RSA) cryptographic algorithm. Index Terms — database-as-a-service(DAS), security, access control, outsourced database.